CVE-2017-7472

Advisory lineage Upstream: 0 Downstream: 17
Modified
Published: 11 May 2017, 19:00
Last modified:05 Aug 2024, 16:04

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
5.5 MEDIUM
v3.0 (nvd)
EPSS Score
0.5% LOW
1% probability -0.43%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

11 May 2017, 19:00
Published
Vulnerability first disclosed
05 Aug 2024, 16:04
Last Modified
Vulnerability information updated

Description

The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls.

CVSS Metrics

  • v3.0MEDIUMScore: 5.5CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 4.9AV:L/AC:L/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 0.50% Percentile: 66%

Techniques & Countermeasures

  • CWE-404Improper Resource Shutdown or Release

    The product does not release or incorrectly releases a resource before it is made available for re-use.

Affected Systems

  • linuxlinux_kernel

    ≤ 4.10.12

References (15)